Privacy Policy
Last updated: May 2026
PaperTalk (“we”, “our”, “us”) is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights under applicable law, including the EU General Data Protection Regulation (GDPR).
1. What data we collect
- Account data: email address and hashed password when you sign up.
- Documents: PDF files you upload for processing.
- Chat messages: questions you ask and the AI responses generated.
- Usage data: page views, feature usage, and error logs to improve the service.
- Payment data: processed by Stripe. We never see or store your full card number.
2. How we use your data
- To provide and improve the PaperTalk service.
- To process your documents and generate AI responses.
- To send transactional emails (account confirmation, password reset, receipts).
- We do NOT use your documents or chat messages to train AI models.
3. Where data is stored
Your data is stored on Supabase infrastructure in the EU (Frankfurt region). Document embeddings and chat data remain within the EU. When you send a message, the relevant text excerpts are sent to Anthropic (Claude) and OpenAI for processing — both companies have data processing agreements compliant with EU standards.
4. Data retention
We retain your data for as long as your account is active. When you delete a document, it is permanently removed from storage and database within 30 days. When you delete your account, all associated data is permanently deleted.
5. Your rights (GDPR)
As an EU resident, you have the right to:
- Access your personal data.
- Rectify inaccurate data.
- Eraseyour data (“right to be forgotten”).
- Export your data in a portable format.
- Object to processing of your data.
- Restrict processing in certain circumstances.
To exercise any of these rights, email us at support@papertalk.app.
6. Cookies
We use only essential cookies required for authentication and session management. We do not use tracking cookies, analytics cookies, or third-party advertising cookies.
7. Third-party services
- Supabase: authentication, database, file storage (EU).
- Anthropic (Claude): AI chat responses. Document excerpts are sent for processing but not stored or used for training.
- OpenAI: text embeddings only. Short text excerpts are sent for vector generation.
- Stripe: payment processing.
- Vercel: hosting and deployment.
8. Changes to this policy
We may update this policy from time to time. We'll notify registered users by email of any material changes.
9. Contact
For privacy questions or data requests, email support@papertalk.app.